Not all MFA is equal.
"We have MFA" isn't a yes/no question — it's a spectrum. Here's how the common methods stack up, best to worst.
Passkeys — the best option available
Built on your device's fingerprint, face scan, or PIN. There's no code to steal, no shared secret to phish — the login is tied to the physical device. NIST and the FIDO Alliance both classify this as "phishing-resistant," a tier above everything else on this list.
Authenticator app codes — good, and widely supported
Apps like Google Authenticator or Microsoft Authenticator generate a rotating code. Better than SMS, but a determined attacker can still trick someone into typing the code into a fake login page in real time.
SMS text codes — better than nothing, but the weakest option
Vulnerable to SIM-swap attacks and interception. Still far better than a password alone, but if it's your only MFA option, it should be a stepping stone, not the destination.
The practical takeaway: use passkeys wherever a service supports them well, and keep an authenticator app as your fallback. Reserve SMS for services that don't offer anything better yet.
Official setup guides, by platform.
These go directly to the source — Google, Microsoft, and leading password managers keep these updated as their own products change, which is more reliable than any third-party walkthrough (including this one).
Google Workspace — 2-Step Verification
Official admin guide for enabling passkeys and MFA org-wideMicrosoft Entra ID — Enable Passkeys (FIDO2)
Official Microsoft Learn guide for Microsoft 365 / Entra ID adminsBitwarden — Passkey Setup
For teams using a password manager as their passkey vaultNIST SP 800-63B
The federal digital identity standard that defines "phishing-resistant" MFAHow we recommend rolling this out.
Don't try to flip everything on at once — a staged rollout avoids lockouts and confused employees.
Email and financial accounts first
These are the accounts attackers target hardest, and the ones with the most damage if compromised. Start here.
Admin and privileged accounts next
Anyone with elevated access — IT admins, finance approvers, executives — should be prioritized right after email.
Critical business SaaS tools
CRM, accounting software, project management — anywhere sensitive company or customer data lives.
Everything else, company-wide
Once the high-value accounts are locked down, extend the same standard to every account and every employee.